Traffic characteristics mechanism for detecting rogue access point in local area network

Rogue Access Point (RAP) is a network vulnerability involving illicit usage of wireless access point in a network environment. The existence of RAP can be identified using network traffic inspection. The purpose of this thesis is to present a study on the use of local area network (LAN) traffic char...

Full description

Saved in:
Bibliographic Details
Main Author: Amran, Ahmad
Format: Thesis
Language:en
en
Published: 2015
Subjects:
Online Access:https://etd.uum.edu.my/5380/1/s91703.pdf
https://etd.uum.edu.my/5380/2/s91703_abstract.pdf
https://etd.uum.edu.my/5380/
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1833436509761437696
author Amran, Ahmad
author_facet Amran, Ahmad
author_sort Amran, Ahmad
building UUM Library
collection Institutional Repository
content_provider Universiti Utara Malaysia
content_source UUM Electronic Theses
continent Asia
country Malaysia
description Rogue Access Point (RAP) is a network vulnerability involving illicit usage of wireless access point in a network environment. The existence of RAP can be identified using network traffic inspection. The purpose of this thesis is to present a study on the use of local area network (LAN) traffic characterisation for typifying wired and wireless network traffic through examination of packet exchange between sender and receiver by using inbound packet capturing with time stamping to indicate the existence of a RAP. The research is based on the analysis of synchronisation response (SYN/ACK), close connection respond (FIN/ACK), push respond (PSH/ACK), and data send (PAYLOAD) of the provider’s flags which are paired with their respective receiver acknowledgment (ACK). The timestamp of each pair is grouped using the Equal Group technique, which produced group means. These means were then categorised into three zones to form zone means. Subsequently, the zone means were used to generate a global mean that served as a threshold value for identifying RAP. A network testbed was developed from which real network traffic was captured and analysed. A mechanism to typify wired and wireless LAN traffic using the analysis of the global mean used in the RAP detection process has been proposed. The research calculated RAP detection threshold value of 0.002 ms for the wired IEEE 802.3 LAN, while wireless IEEE 802.11g is 0.014 ms and IEEE 802.11n is 0.033 ms respectively. This study has contributed a new mechanism for detecting a RAP through traffic characterisation by examining packet communication in the LAN environment. The detection of RAP is crucial in the effort to reduce vulnerability and to ensure integrity of data exchange in LAN
format Thesis
id my.uum.etd-5380
institution Universiti Utara Malaysia
language en
en
publishDate 2015
record_format eprints
spelling my.uum.etd-53802021-03-18T03:56:13Z https://etd.uum.edu.my/5380/ Traffic characteristics mechanism for detecting rogue access point in local area network Amran, Ahmad TK7885-7895 Computer engineering. Computer hardware Rogue Access Point (RAP) is a network vulnerability involving illicit usage of wireless access point in a network environment. The existence of RAP can be identified using network traffic inspection. The purpose of this thesis is to present a study on the use of local area network (LAN) traffic characterisation for typifying wired and wireless network traffic through examination of packet exchange between sender and receiver by using inbound packet capturing with time stamping to indicate the existence of a RAP. The research is based on the analysis of synchronisation response (SYN/ACK), close connection respond (FIN/ACK), push respond (PSH/ACK), and data send (PAYLOAD) of the provider’s flags which are paired with their respective receiver acknowledgment (ACK). The timestamp of each pair is grouped using the Equal Group technique, which produced group means. These means were then categorised into three zones to form zone means. Subsequently, the zone means were used to generate a global mean that served as a threshold value for identifying RAP. A network testbed was developed from which real network traffic was captured and analysed. A mechanism to typify wired and wireless LAN traffic using the analysis of the global mean used in the RAP detection process has been proposed. The research calculated RAP detection threshold value of 0.002 ms for the wired IEEE 802.3 LAN, while wireless IEEE 802.11g is 0.014 ms and IEEE 802.11n is 0.033 ms respectively. This study has contributed a new mechanism for detecting a RAP through traffic characterisation by examining packet communication in the LAN environment. The detection of RAP is crucial in the effort to reduce vulnerability and to ensure integrity of data exchange in LAN 2015 Thesis NonPeerReviewed text en https://etd.uum.edu.my/5380/1/s91703.pdf text en https://etd.uum.edu.my/5380/2/s91703_abstract.pdf Amran, Ahmad (2015) Traffic characteristics mechanism for detecting rogue access point in local area network. PhD. thesis, Universiti Utara Malaysia.
spellingShingle TK7885-7895 Computer engineering. Computer hardware
Amran, Ahmad
Traffic characteristics mechanism for detecting rogue access point in local area network
title Traffic characteristics mechanism for detecting rogue access point in local area network
title_full Traffic characteristics mechanism for detecting rogue access point in local area network
title_fullStr Traffic characteristics mechanism for detecting rogue access point in local area network
title_full_unstemmed Traffic characteristics mechanism for detecting rogue access point in local area network
title_short Traffic characteristics mechanism for detecting rogue access point in local area network
title_sort traffic characteristics mechanism for detecting rogue access point in local area network
topic TK7885-7895 Computer engineering. Computer hardware
url https://etd.uum.edu.my/5380/1/s91703.pdf
https://etd.uum.edu.my/5380/2/s91703_abstract.pdf
https://etd.uum.edu.my/5380/
url_provider http://etd.uum.edu.my/